2026年9月23日星期三

F5 BIG-IP Remote Code Execution Vulnerability

F5 BIG-IP Remote Code Execution Vulnerability

Release Date: 23 Sep 2026

A vulnerability was identified in F5 BIG-IP. A remote attacker could exploit this vulnerability to trigger remote code execution on the targeted system.

 

Note:

CVE-2026-94127  is being exploited in the wild. This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Hence, the risk level is rated as High Risk.


Impact

  • Remote Code Execution

System / Technologies affected

BIG-IP APM

 

  • Versions 17.1.0 - 17.1.3
  • Versions 17.5.0 - 17.5.1
  • Versions 21.1.0

 


Solutions

Please visit the vendor web-site for more details.

 

Apply workarounds issued by the vendor:


Vulnerability Identifier


Source


Related Link

 


沒有留言:

發佈留言

F5 BIG-IP 遠端執行程式碼漏洞

F5 BIG-IP 遠端執行程式碼漏洞 發佈日期 : 2026 年 09 月 23 日 於 F5 BIG-IP 發現一個漏洞。遠端攻擊者可利用這漏洞,於目標系統觸發遠端執行程式碼狀況。   注意: CVE-2026-94127 正被廣泛利用。此漏洞僅在 B...